Created on
08-05-2025
10:36 AM
Edited on
08-06-2025
09:35 AM
By
Stephen_G
Description | This article describes the required configuration to establish a dial-up IPsec VPN using IKEv2 between a Windows 11 device and a FortiGate firewall. It includes settings for VPN phase configuration, user authentication, and proposal compatibility with the built-in Windows VPN client. | ||||||||||
Scope | FortiGate configured with IKEv2 IPsec VPN for remote access and Windows 11 devices using the native IKEv2 VPN client. | ||||||||||
Solution |
FortiGate Configuration.
Windows 11 VPN Client Configuration:
Optional: Registry Key for NAT-T:
When FortiGate is behind NAT, use the following registry key on the Windows client to ensure compatibility:
Reboot is required after applying the key.
Proposal Compatibility:
Ensure proposals used on the FortiGate match what is supported by Windows IKEv2 client:
Recommended: 'aes256-sha256' and 'dhgrp 14'.
Troubleshooting Tips:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.